 <?php 



include("opendb.php");

$username = $_GET['username'];

$password = $_GET['password'];

$username = 'matt';

$group = $_GET['group'];
$group = '5';

include("functions.php");

/*$res = isValidUser($username,$password);

if($res!=1) {

exit;

echo "0";

}*/

$queryu = "select ID from Users where Username = '".$username."'";
$resultu = mysql_query($queryu) or die ("SQL Error".mysql_error());
$row = mysql_fetch_assoc($resultu);

include("opendb_crm.php");
$query1 = "select * from document_grps where group_id = '".$group."' and group_owner = '".$row['ID']."'";
$result1 = mysql_query($query1) or die ("SQL Error".mysql_error());
$row1 = mysql_fetch_assoc($result1);
$xml = "<docs>";

$doc_id = explode(",", $row1['document_ids']);
			foreach($doc_id as $id)
				{
				$xml .= "<doc>";
				$dsql = "Select d.document_name, d.id from documents d where created_by = '".$row['ID']."' and id = '".$id."'";
				$dresult = mysql_query($dsql) or die ("SQL Error".mysql_error());
				$drow=mysql_fetch_assoc($dresult);
				
				$xml .= "<id>".$drow['id']."</id>";
				$xml .= "<name><![CDATA[".$drow['document_name']."]]></name>";
				$xml .= "</doc>";
				
				}


$xml .= "</docs>";

echo $xml;

?>